“We generally have the agents do as much of the investigation as possible,” Notch said. “We’ll have AI-powered automation to take actions like resetting the identity verification on a laptop. But generally speaking, we want humans reviewing some of the AI work to make sure that it’s producing the best outcomes.”
At Salesforce, Fraser-Rahim said proactive enterprises that take a strategic approach to AI defense might even hold certain advantages over agentic attackers. Still, no one is downplaying the threat.And it’s not only bad actors. Frontier AI models can also pose agentic cybersecurity risks, if not carefully contained. That’s why every agentic enterprise must ensure that no AI model has unchecked authority that could turn an honest error into a mission-critical emergency.
A readership poll by the trade publication Dark Reading found that 48% of security professionals now identify agentic AI and autonomous systems as the digital world’s most dangerous attack vector. Furthermore, a June report from Anthropic found that “high risk,” AI-enabled threats rose to 56% of total cyber incidents, up from 33% a year earlier.
“Cyberattacks are becoming more autonomous,” the Anthropic report said, “and the fact that AI can be used to chain together many parts of the attack means that the old ways of differentiating high- from low-risk actors are no longer as effective.”Kelly McCracken, Deputy Chief Information Security Officer and SVP of Security Operations at Salesforce, said an old security maxim has new urgency: “We have to be right every time. The threat actors only have to be right one time.”








